<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>Mikrotik.moscow [тема: DNS на точке доступа и изоляция сетей.]</title>
		<link>http://mikrotik.moscow</link>
		<description>Новое в теме DNS на точке доступа и изоляция сетей. форума RouterOS на сайте Mikrotik.moscow [mikrotik.moscow]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Thu, 20 Aug 2026 14:15:26 -0400</pubDate>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message216002">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			/interface ethernet switch<br />set 0 mirror-source=none mirror-target=none name=switch1 switch-all-ports=yes<br />/interface ethernet switch port<br />set 0 vlan-header=leave-as-is vlan-mode=fallback<br />set 1 vlan-header=leave-as-is vlan-mode=fallback<br />set 2 vlan-header=leave-as-is vlan-mode=fallback<br />set 3 vlan-header=leave-as-is vlan-mode=fallback<br />set 4 vlan-header=leave-as-is vlan-mode=fallback<br />set 5 vlan-header=leave-as-is vlan-mode=fallback <br />
			<i>22.08.2012 18:22:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message216002</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message216002</guid>
			<pubDate>Wed, 22 Aug 2012 18:22:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message216001">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Ах, нашёл переключатель в Winbox Switch-Name,switch1-Type,Atheros 8316. Под портом показывает, что это свитч на всех ethers, с 1 по 5, а затем имя,switch1 cpu VLAN Mode fallback. Не знаю и не могу найти в терминале способ вывести информацию о свитче. <br />
			<i>22.08.2012 17:14:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message216001</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message216001</guid>
			<pubDate>Wed, 22 Aug 2012 17:14:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message216000">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Хаха, я не говорил, что ты не можешь использовать Winbox! Я просто не знаю, как тебе это показать. Загружать .jpg — это куча возни. Я имел в виду, есть ли способ показать тебе результат из Терминала, потому что я не все команды знаю. Ладно. ARP показывает все IP-адреса на правильном этере. Определенно нет Бриджа. Switch я не знаю.<br /><br />[admin@RB450G] &gt;&gt; /ip arp print<br /><br />Flags: X - disabled, I - invalid, H - DHCP, D - dynamic<br /><br /> # &nbsp; ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; MAC-ADDRESS &nbsp; &nbsp; &nbsp; INTERFACE<br /> 0 D 192.168.3.4 &nbsp; &nbsp; 00:27:22:EC:6F:81 ether3<br /> 1 D 192.168.0.170 &nbsp; 00:10:75:06:C1:80 ether1<br /> 2 D 192.168.11.1 &nbsp; &nbsp;00:24:A5:BD:5F:E6 ether2<br /> 3 D 192.168.3.15 &nbsp; &nbsp;00:27:22:7A:D5:6F ether3<br /> 4 D 192.168.3.2 &nbsp; &nbsp; 00:27:22:EC:6F:81 ether3<br /> 5 D 192.168.0.164 &nbsp; 00:27:22:72:C7:65 ether1<br /> 6 D 192.168.3.3 &nbsp; &nbsp; 00:27:22:EC:6F:81 ether3<br /> 7 D 192.168.3.17 &nbsp; &nbsp;50:CC:F8:20:CA:83 ether3<br /> 8 D 192.168.0.222 &nbsp; 00:90:0B:10:91:48 ether1<br /> 9 D 192.168.3.20 &nbsp; &nbsp;00:27:22:EC:6F:81 ether3<br />10 D 192.168.0.5 &nbsp; &nbsp; 1C:6F:65:DB:2B:18 ether1<br />11 D 192.168.0.3 &nbsp; &nbsp; 00:21:91:91:1E:99 ether1<br />12 D 192.168.0.159 &nbsp; 00:27:22:72:C7:65 ether1<br />13 D 192.168.0.6 &nbsp; &nbsp; 00:24:8C:22:C8:9B ether1<br /><br />Что значит этот switch1?<br /><br />[admin@RB450G] &gt;&gt; /interface ethernet print<br /><br />Flags: X - disabled, R - running, S - slave<br /><br /> # &nbsp; &nbsp;NAME &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;MTU MAC-ADDRESS &nbsp; &nbsp; &nbsp; ARP &nbsp; &nbsp; &nbsp; &nbsp;MASTER-PORT &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; SWITCH<br /> 0 R &nbsp;;;; Lan<br /> &nbsp; &nbsp; &nbsp;ether1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:BB enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;switch1<br /> 1 R &nbsp;;;; ADSL Modem<br /> &nbsp; &nbsp; &nbsp;ether2 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:BC enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;switch1<br /> 2 R &nbsp;;;; Hotspot<br /> &nbsp; &nbsp; &nbsp;ether3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:BD enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;switch1<br /> 3 &nbsp; &nbsp;ether4 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:BE enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;switch1<br /> 4 &nbsp; &nbsp;ether5 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:BF enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;switch1 <br />
			<i>22.08.2012 17:05:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message216000</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message216000</guid>
			<pubDate>Wed, 22 Aug 2012 17:05:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215999">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Могу использовать Winbox. Если ты в Winbox, проверь вкладку “Bridge”. Мостов не назначено? Значит, есть причина, почему твой IP 192.168.0.222 отображается в “/ip hotspot host”. Может, что-то с настройками моста или коммутатора? <br />
			<i>22.08.2012 16:35:00, SurferTim.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215999</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215999</guid>
			<pubDate>Wed, 22 Aug 2012 16:35:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215998">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Смотрю я это в Winbox. Не знаю команду для терминала. Определённо на ether3. Servers-hotspot1-ether3-hotpool-hsprof1 <br />
			<i>22.08.2012 16:23:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215998</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215998</guid>
			<pubDate>Wed, 22 Aug 2012 16:23:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215997">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Посмотри на "/ip hotspot". Убедись, что твой хотспот назначен на ether3, а не на ether1. <br />
			<i>22.08.2012 16:11:00, SurferTim.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215997</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215997</guid>
			<pubDate>Wed, 22 Aug 2012 16:11:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215996">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Ну и зачем? Кабель идёт в ether1, ether1 находится в сети 192.168.0.0, а IP-адрес 192.168.0.222. Как же он оказался на ether3 hotspot? <br />
			<i>22.08.2012 16:08:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215996</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215996</guid>
			<pubDate>Wed, 22 Aug 2012 16:08:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215995">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Это говорит о том, что устройство подключено к интерфейсу точки доступа (ether3), а не к локальной сети (ether1). 4 D 00:27:22:EC:6F:81 192.168.0.222 192.168.3.20 hotspot1 5m <br />
			<i>22.08.2012 15:55:00, SurferTim.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215995</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215995</guid>
			<pubDate>Wed, 22 Aug 2012 15:55:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215994">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			[admin@RB450G] &gt;&gt; ip hotspot host print<br />Флаги: S - статический, H - DHCP, D - динамический, A - авторизован, P - обойден<br /> # &nbsp; &nbsp;MAC-ADDRESS &nbsp; &nbsp; &nbsp; ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; TO-ADDRESS &nbsp; &nbsp; &nbsp;SERVER &nbsp; &nbsp; IDLE-TIMEOUT<br /> 0 D &nbsp;00:27:22:7A:D5:6F 192.168.3.201 &nbsp; 192.168.3.15 &nbsp; &nbsp;hotspot1 &nbsp; 5m &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<br /> 1 DA 50:CC:F8:20:CA:83 41.14.219.146 &nbsp; 192.168.3.18 &nbsp; &nbsp;hotspot1 &nbsp;<br /> 2 &nbsp;A 50:CC:F8:20:CA:83 192.168.3.19 &nbsp; &nbsp;192.168.3.17 &nbsp; &nbsp;hotspot1 &nbsp;<br /> 3 D &nbsp;00:27:22:EC:6F:81 192.168.0.5 &nbsp; &nbsp; 192.168.3.16 &nbsp; &nbsp;hotspot1 &nbsp; 5m &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<br /> 4 D &nbsp;00:27:22:EC:6F:81 192.168.0.222 &nbsp; 192.168.3.20 &nbsp; &nbsp;hotspot1 &nbsp; 5m &nbsp; <br /> &nbsp; &nbsp; &nbsp; <br />[admin@RB450G] &gt;&gt; /ip hotspot active print<br />Флаги: R - radius, B - blocked<br /> # &nbsp; &nbsp;USER &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; UPTIME &nbsp; &nbsp; &nbsp; SESSION-TIME-LEFT IDLE-TIMEOUT<br /> 0 &nbsp; &nbsp;50:CC:F8:2... 192.168.3.17 &nbsp; &nbsp;55s &nbsp; &nbsp; &nbsp; &nbsp; <br /> 1 &nbsp; &nbsp;50:CC:F8:2... 192.168.3.18 &nbsp; &nbsp;56s Вот о чем я говорю. 50:CC:F8:20:CA:83 – это мой мобильный телефон, 00:27:22:EC:6F:81 – IP-адрес Corder. 192.168.0.222 преобразован в 192.168.3.20. 192.168.3.201 – AP. 192.168.0.5 – ПК в сети 192.168.0.0, преобразован в 192.168.3.16. Почему мой телефон получает два IP-адреса? Камеры записываются IP-Corder (NVR) постоянно, но отображается только IP-адрес NVR, а не IP-адреса камер? <br />
			<i>22.08.2012 15:53:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215994</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215994</guid>
			<pubDate>Wed, 22 Aug 2012 15:53:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215993">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Посмотри на "/ip hotspot host". Там отображаются результаты универсального NAT для hotspot. Там показываются эти перенаправления? Посмотри на адрес (фактический адрес устройства) и to-address (адрес, видимый за пределами интерфейса hotspot). Если есть вопросы, выкладывай эту часть. <br />
			<i>22.08.2012 15:24:00, SurferTim.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215993</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215993</guid>
			<pubDate>Wed, 22 Aug 2012 15:24:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215992">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			ARP переводит все мои IP-адреса в сеть 192.168.3.0. (Кажется, это ARP?) Например, 192.168.0.222 в 192.168.3.3. Я не хочу, чтобы IP-адреса из моей сети 192.168.0.0 переводились в сеть .3.0. <br />
			<i>22.08.2012 15:18:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215992</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215992</guid>
			<pubDate>Wed, 22 Aug 2012 15:18:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215991">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Эфир 2 — это интерфейс WAN, верно? Да. Ты пробовал войти, зайдя, например, на <noindex><a href="http://www.google.com" target="_blank" rel="nofollow" >www.google.com</a></noindex> или на что-то подобное, а потом попробовать адрес 192.168.0.222? Да, никакой разницы не заметил. <br />
			<i>22.08.2012 14:55:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215991</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215991</guid>
			<pubDate>Wed, 22 Aug 2012 14:55:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215990">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Окей, сделал. Только что перед этим я тестировал 192.168.0.222 – работало, но как-то раздражающе медленно, и две IP-камеры не смогли подключиться. Я заметил, что проблема возникает периодически, и меня ничуть не удивило, что устройство по IP найти не удалось. Потом я добавил правило и убрал ещё два. Теперь не могу подключиться, и в адресной строке браузера получаю <noindex><a href="http://hotspot.dns/login?dst=http%3A%2F%2F192.168.0.222%2F" target="_blank" rel="nofollow" >http://hotspot.dns/login?dst=http%3A%2F%2F192.168.0.222%2F</a></noindex> с сообщением "Не удалось найти удаленный сервер". Не думаю, что это связано с изменениями. Если бы я ещё раз попробовал, то, скорее всего, произошло бы то же самое. (По опыту) Последний вывод nat. [admin@RB450G] /ip firewall&gt; nat print<br />Flags: X - disabled, I - invalid, D - dynamic <br /> 0 X ;;; место для правил hotspot<br /> &nbsp; &nbsp; chain=unused-hs-chain action=passthrough <br /><br /> 1 &nbsp; chain=srcnat action=masquerade out-interface=ether2 <br />
			<i>22.08.2012 14:50:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215990</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215990</guid>
			<pubDate>Wed, 22 Aug 2012 14:50:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215989">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я бы использовал srcnat (маскараду) только для WAN-интерфейса. Добавь это, а затем убери остальные два srcnat. /ip firewall nat<br />add chain=srcnat action=masquerade out-interface=ether2. Ether2 — это WAN-интерфейс, верно? Ты пробовал зайти в систему, например, через <noindex><a href="http://www.google.com" target="_blank" rel="nofollow" >www.google.com</a></noindex>, а потом попробовать адрес 192.168.0.222? <br />
			<i>22.08.2012 14:26:00, SurferTim.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215989</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215989</guid>
			<pubDate>Wed, 22 Aug 2012 14:26:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215988">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			[admin@RB450G] /ip firewall&gt; filter print<br />Флаги: X - отключено, I - недействительно, D - динамически<br /> 0 X ;;; сюда правила для hotspot<br /> &nbsp; &nbsp; chain=unused-hs-chain action=passthrough <br /><br />[admin@RB450G] /ip firewall&gt; nat print<br />Флаги: X - отключено, I - недействительно, D - динамически<br /> 0 X ;;; сюда правила для hotspot<br /> &nbsp; &nbsp; chain=unused-hs-chain action=passthrough <br /><br /> 1 &nbsp; ;;; Маскируем LAN интерфейс<br /> &nbsp; &nbsp; chain=srcnat action=masquerade src-address=192.168.0.0/24 dst-address=0.0.0.0/0 <br /><br /> 2 &nbsp; ;;; маскируем сеть hotspot<br /> &nbsp; &nbsp; chain=srcnat action=masquerade to-addresses=0.0.0.0 src-address=192.168.3.0/24 <br />
			<i>22.08.2012 14:19:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215988</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215988</guid>
			<pubDate>Wed, 22 Aug 2012 14:19:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215987">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			В общем, всё в порядке, пока ты не заходишь по адресам в локальной сети. Ты же знаешь, что надо быть авторизованным (или добавить IP локальной сети в "walled garden"), чтобы выходить за пределы локальной сети точки доступа, и у тебя будут проблемы с другими устройствами в этой локальной сети, если не отключить универсальный NAT точки доступа. Вроде бы всё нормально на первый взгляд, может, дело в фаерволе? Как насчёт этого? /ip firewall filter /ip firewall nat edit: Также попробуй это: /ip hotspot profile<br />set 1 login-by=http-chap <br />
			<i>22.08.2012 14:11:00, SurferTim.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215987</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215987</guid>
			<pubDate>Wed, 22 Aug 2012 14:11:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215986">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я бы начал с того, чтобы удалить dns-name из точки доступа. Честно говоря, понятия не имею, как это сделать. <br />
			<i>22.08.2012 14:03:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215986</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215986</guid>
			<pubDate>Wed, 22 Aug 2012 14:03:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215985">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			# АДРЕС &nbsp; &nbsp; &nbsp; &nbsp; СЕТЬ &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ИНТЕРФЕЙС<br />0 &nbsp;;;; Hotspot Interface<br /> &nbsp; &nbsp;192.168.3.1/24 &nbsp; &nbsp; 192.168.3.0 &nbsp; &nbsp; ether3<br />1 &nbsp;;;; ADSL Interface<br /> &nbsp; &nbsp;192.168.11.25/24 &nbsp; 192.168.11.0 &nbsp; &nbsp;ether2<br />2 &nbsp;;;; Lan Interface<br /> &nbsp; &nbsp;192.168.0.1/24 &nbsp; &nbsp; 192.168.0.0 &nbsp; &nbsp; ether1<br /><br /># &nbsp; DST-ADDRESS &nbsp; &nbsp; &nbsp; &nbsp;PREF-SRC &nbsp; &nbsp; &nbsp; &nbsp;GATEWAY &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;DISTANCE<br />0 A S &nbsp;;;; 192.168.11.1 Modem<br /> &nbsp; &nbsp; &nbsp; &nbsp;0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;192.168.11.1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1<br />1 ADC &nbsp;192.168.0.0/24 &nbsp; &nbsp; 192.168.0.1 &nbsp; &nbsp; ether1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br />2 ADC &nbsp;192.168.3.0/24 &nbsp; &nbsp; 192.168.3.1 &nbsp; &nbsp; ether3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br />3 ADC &nbsp;192.168.11.0/24 &nbsp; &nbsp;192.168.11.25 &nbsp; ether2 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br /><br /># &nbsp; &nbsp;NAME &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;MTU MAC-ADDRESS &nbsp; &nbsp; &nbsp; ARP &nbsp; &nbsp; &nbsp; &nbsp;MASTER-PORT &nbsp; &nbsp; &nbsp;SWITCH<br />0 R &nbsp;;;; Lan<br /> &nbsp; &nbsp; &nbsp;ether1 &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:** enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; switch1<br />1 R &nbsp;;;; ADSL Modem<br /> &nbsp; &nbsp; &nbsp;ether2 &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:** enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; switch1<br />2 R &nbsp;;;; Hotspot<br /> &nbsp; &nbsp; &nbsp;ether3 &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:** enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; switch1<br />3 &nbsp; &nbsp;ether4 &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:** enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; switch1<br />4 &nbsp; &nbsp;ether5 &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:** enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; switch1<br /><br />[admin@RB450G] &gt; /ip bridge<br />bad command name bridge (line 1 column 5)<br /><br />Всё вышеперечисленное – это установка перед настройкой Hotspot. Ниже – конфигурация после установки.<br /><br />[admin@RB450G] &gt; /ip address print<br />Flags: X - отключен, I - недействителен, D - динамический<br /><br /># &nbsp; ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;NETWORK &nbsp; &nbsp; &nbsp; &nbsp; INTERFACE<br />0 &nbsp;;;; Hotspot Interface<br /> &nbsp; &nbsp;192.168.3.1/24 &nbsp; &nbsp; 192.168.3.0 &nbsp; &nbsp; ether3<br />1 &nbsp;;;; ADSL Interface<br /> &nbsp; &nbsp;192.168.11.25/24 &nbsp; 192.168.11.0 &nbsp; &nbsp;ether2<br />2 &nbsp;;;; Lan Interface<br /> &nbsp; &nbsp;192.168.0.1/24 &nbsp; &nbsp; 192.168.0.0 &nbsp; &nbsp; ether1<br /><br />[admin@RB450G] &gt; /ip route print<br />Flags: X - отключен, A - активен, D - динамический,<br />C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,<br />B - blackhole, U - unreachable, P - prohibit<br /><br /># &nbsp; &nbsp; &nbsp;DST-ADDRESS &nbsp; &nbsp; &nbsp; &nbsp;PREF-SRC &nbsp; &nbsp; &nbsp; &nbsp;GATEWAY &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;DISTANCE<br />0 A S &nbsp;;;; 192.168.11.1 Modem<br /> &nbsp; &nbsp; &nbsp; &nbsp;0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;192.168.11.1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1<br />1 ADC &nbsp;192.168.0.0/24 &nbsp; &nbsp; 192.168.0.1 &nbsp; &nbsp; ether1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br />2 ADC &nbsp;192.168.3.0/24 &nbsp; &nbsp; 192.168.3.1 &nbsp; &nbsp; ether3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br />3 ADC &nbsp;192.168.11.0/24 &nbsp; &nbsp;192.168.11.25 &nbsp; ether2 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br /><br />[admin@RB450G] &gt; /ip bridge<br />bad command name bridge (line 1 column 5)<br /><br />[admin@RB450G] &gt; /interface ethernet print<br />Flags: X - отключен, R - запущен, S - slave<br /><br /># &nbsp; &nbsp;NAME &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;MTU MAC-ADDRESS &nbsp; &nbsp; &nbsp; ARP &nbsp; &nbsp; &nbsp; &nbsp;MASTER-PORT &nbsp; &nbsp; &nbsp;SW<br />0 R &nbsp;;;; Lan<br /> &nbsp; &nbsp; &nbsp;ether1 &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:** enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; switch1<br />1 R &nbsp;;;; ADSL Modem<br /> &nbsp; &nbsp; &nbsp;ether2 &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:** enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; switch1<br />2 R &nbsp;;;; Hotspot<br /> &nbsp; &nbsp; &nbsp;ether3 &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:** enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; switch1<br />3 &nbsp; &nbsp;ether4 &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:** enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; switch1<br />4 &nbsp; &nbsp;ether5 &nbsp; &nbsp; &nbsp; 1500 D4:CA:6D:34:48:** enabled &nbsp; &nbsp;none &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; switch1<br /><br />Для полноты картины, вот вывод настроек Hotspot:<br />[admin@RB450G] /ip hotspot profile&gt; print<br />Flags: * - по умолчанию<br /><br />0 * name="default" hotspot-address=0.0.0.0 dns-name=""<br /> &nbsp; &nbsp;html-directory=hotspot rate-limit="" http-proxy=0.0.0.0:0<br /> &nbsp; &nbsp;smtp-server=0.0.0.0 login-by=mac,cookie,http-chap,https,http-pap<br /> &nbsp; &nbsp;mac-auth-password="" http-cookie-lifetime=3d ssl-certificate=none<br /> &nbsp; &nbsp;split-user-domain=no use-radius=no<br /><br />1 &nbsp; name="hsprof1" hotspot-address=192.168.3.1 dns-name="hotspot.dns"<br /> &nbsp; &nbsp;html-directory=hotspot rate-limit="" http-proxy=0.0.0.0:0<br /> &nbsp; &nbsp;smtp-server=0.0.0.0 login-by=mac,cookie,http-chap,https,http-pap<br /> &nbsp; &nbsp;mac-auth-password="" http-cookie-lifetime=3d ssl-certificate=none<br /> &nbsp; &nbsp;split-user-domain=no use-radius=no<br /><br />Спасибо за помощь в решении моей проблемы. <br />
			<i>22.08.2012 13:54:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215985</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215985</guid>
			<pubDate>Wed, 22 Aug 2012 13:54:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215984">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я бы начал с удаления dns-имени из точки доступа. Оно там не нужно, оно будет использовать IP-адрес интерфейса точки доступа в адресной строке браузера вместо этого. Может помочь, если ты выложишь вывод команд “/ip address” и “/ip route”. Ни один из ethernet-портов не подключен к коммутатору или мосту, верно? /ip bridge /interface ethernet <br />
			<i>22.08.2012 11:09:00, SurferTim.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215984</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215984</guid>
			<pubDate>Wed, 22 Aug 2012 11:09:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>DNS на точке доступа и изоляция сетей.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215983">DNS на точке доступа и изоляция сетей.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет всем. Это мой первый пост. Я не вижу раздела для представления, поэтому кратко расскажу о себе перед вопросами. Меня зовут Том, мне 53 года, живу в Южной Африке. У меня небольшая гостиница, а мои интересы – компьютеры, программирование и сети. Все самообучался, так что знаний особых нет. Только достаточно, чтобы самому справляться в большинстве ситуаций. Я связываю два сайта по беспроводной связи, примерно в километре друг от друга. У меня есть проводная локальная сеть с 4 ПК: 3 x W7 и 1 x XP. Также у меня в локальной сети сетевой принтер и IPCorder с несколькими IP-камерами. Эта проводная локальная сеть работает в сети 192.168.0.0. Затем у меня есть ADSL-модем в сети 192.168.11.0 и беспроводное соединение в сети 192.168.3.0. У меня есть RB450G, и эти сети подключены к портам 1, 2 и 3 соответственно, а порты 4 и 5 свободны. Я настроил RB450G так, чтобы все три сети работали и был доступ в интернет. Все работает плавно, без сбоев и задержек. Я успешно просканировал IP-адреса во всех трех сетях через Winbox, и все устройства отвечают на ping. У всех устройств в проводной локальной сети статические IP-адреса, а также у беспроводного соединения и точек доступа. Но я хочу запустить Hotspot в сети 192.168.3.0, порт 3. Мне также нужно изолировать проводную локальную сеть от беспроводной сети, так как все мои личные ПК подключены к интерфейсу 1, а все беспроводные устройства и точки доступа – к порту 3, где клиенты будут подключаться к hotspot. Значит, мои гости не должны видеть мои ПК, принтер или IP-камеры. (Если я позволю им смотреть камеры, это очень быстро исчерпает выделенную пропускную способность). Я не знаю, как сделать эту изоляцию, хотя подозреваю, что это очень просто. Я знаю, что могу сделать это на точках доступа, чтобы клиенты не видели друг друга, но хочу заблокировать их от моей личной сети тоже с помощью Mikrotik. Что касается hotspot, то он работает, и клиенты могут подключаться с помощью HTTP или Mac. (На самом деле я разрешил все методы, кроме Trial). Я даю своим гостям имя пользователя и пароль, а моя семья подключается по Mac-адресу своих устройств. Так что все хорошо, у них есть доступ в интернет через hotspot. Однако! Как только я активирую этот hotspot, у меня возникают проблемы с DNS, с IPCorder ((NVR), сетевым принтером и общие сбои и задержки в проводной сети. Я правильно настроил DNS и разрешил удаленные запросы, иначе у меня не было бы доступа в интернет во всех сетях. DHCP-сервер выдает IP-адреса устройствам, подключающимся через точки доступа. IP-адреса по DHCP получают только устройства, подключающиеся через точки доступа. DNS на сервере hotspot – виновник. DNS-серверы на сервере hotspot те же, что и в моей DNS-настройке, и они заполняются автоматически. Я дал имя DNS локального сервера hotspot как hotspot.dns, поскольку, видимо, это может быть что угодно, если в имени есть точка. Проблема проявляется в форме доступа через браузер. Как только я захожу на 192.168.0.222 (IP Corder), я получаю сообщение о hotspot.dns в адресной строке браузера и затем перенаправление, и IP Corder начинает вести себя странно, например, переходит в режим настройки, и я не могу получить доступ к режиму просмотра камер. Также сетевой принтер (192.168.0.15) становится недоступным (тоже с сообщением о hotspot.dns), а Windows-сеть становится нестабильной, не всегда находя все ПК. Я не понимаю, почему hotspot на порту 3 (192.168.3.0) и совершенно другой сети, вмешивается в мою локальную сеть на порту 1 (192.168.0.0)? Кстати, у меня все еще есть доступ в интернет в обеих сетях. Так что это две проблемы. Изоляция DNS на Hotspot. Спасибо за ваше время, Том. <br />
			<i>21.08.2012 19:33:00, TomKriek.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215983</link>
			<guid>http://mikrotik.moscow/forum/forum57/57360-dns-na-tochke-dostupa-i-izolyatsiya-setey./message215983</guid>
			<pubDate>Tue, 21 Aug 2012 19:33:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
	</channel>
</rss>
